CrawlCheck

Findings · 2026-08-19 · By · 0 views

33 AI visibility tools scanned: a third publish llms.txt, none an entity map

Thirty-three SEO and AI-visibility vendors, run through the same scanner they would point at you.

Every tool in this corpus sells some form of judgement about other people’s websites. So we pointed our scanner at thirty-three of them — crawler-identity checks, machine files, cache behaviour, render path, the same battery a paying customer gets — and recorded what came back.

What the August run found #

The spread was wide. The best vendor site we measured scored 92 of 100; the worst that completed a scan, 41. The median site in this corpus delivers under one visible word in twenty bytes of payload — the rest is markup and script. These are the people who sell payload advice.

Roughly a third of the vendors publish an llms.txt. Not one that we scanned publishes an entity map. Several serve a cached copy of a machine file that no longer matches what their origin answers — which means an AI crawler and a human can be told two different things, by the company that audits exactly that.

One site could not be measured at all: every path we requested, including one that cannot exist, answered identically. That is a firewall speaking, not a website, and it gets its own story — because the first time we met it, we got it wrong.

The list is now a page that re-measures itself #

A dated table of vendor scores goes stale the week it is published, and a stale accusation is unfair to the vendor who fixed the thing. So the August spreadsheet became the directory: a narrower list of 25 tools with a category each, re-scanned on a rolling basis, with a dated ledger of what moved. It is a different population from the 33 in the first run — curated to tools that sell a judgement about other sites, not every domain the crawl happened to touch — so the two sets should not be read as one group changing over time.

First run, 2026-08-19Directory, 2026-09-09
Vendors33 scanned25 listed, 23 graded
Highest score9284 (Sitebulb)
Lowest completed scan4144
Mediannot published78
Publish an llms.txtroughly a third11 of 23
Publish an entity map00 of 23
Refused the scanner12, listed as refused and not graded

The directory column is a snapshot of a page that regenerates; open it for today’s figures. Every card links the evidence the number came from.

What the second column says that the first could not #

Two things. First, the entity-map count has not moved: zero of twenty-three, three weeks later, on the sites of companies whose product includes telling you to publish structured data about yourself. That is not a lag. Second, the refusals are now a category rather than an anecdote. A vendor whose edge challenges datacentre traffic is listed as refused this scanner — not graded, with no number, because a number would be our vantage point dressed as their defect. Two of the twenty-five sit there today.

The grades themselves clustered. Twenty of the twenty-three graded sites landed between 62 and 84 — one B-to-D band, a few points apart, on a test every one of them would pass a customer through. The outliers are more telling than the middle: a site crawler at 44 with nine findings, and an enterprise SEO platform with zero findings and a 65, which is what a clean scan of a page that says almost nothing looks like.

How to read a vendor’s own score #

Each directory card carries three numbers under the grade, and they answer three different questions. Reach: can each named crawler get the page at all, and is any of them turned away or handed something different. Read: of what arrives, how much is text a machine can use rather than markup, script and styling wrapped around it. Quote: is there a fact on the page an answer engine could lift and attribute — a stated number, a dated claim, an answered question — or only adjectives.

The three do not move together, and the cases where they diverge are the useful ones. Two AI-visibility monitors today score 100 on reach and 35 on quote: every crawler is welcome, and there is almost nothing on the page worth repeating. A site crawler scores 90 on reach and 48 on read: the door is open and the room is mostly furniture. A single blended score would hide both. The columns are there so a vendor arguing with the number has to say which one.

The ledger under the table records each change with a date, so a vendor who ships an llms.txt on Tuesday is shown doing so on Tuesday, and a vendor whose cached machine file drifted from its origin is shown when it drifted and when it was fixed. That is the part a spreadsheet could never do, and the part that makes the page fair to argue with.

Two disclosures #

A measurement without them is marketing. First: these figures are a snapshot of the day each scan ran; sites change, and a vendor who fixes their machine layer tomorrow deserves the better number — reports here regenerate live, so following any link shows today’s state, not the day we wrote this. Second: crawlcheck.io does not appear in its own corpus. This scanner structurally cannot grade its own site from inside. We publish that limit rather than hide it: check our files from any client you like, or read what happened when a competitor graded us.

The uncomfortable summary #

The industry that grades machine readability is, on its own machine layer, about average. The average is low. The directory exists so that sentence has to keep being true to stay on the page.

Live, as you read this: the corpus now holds 189,169 domains across 3,137 scans. The figures in this piece were measured on the date above; this line is not.

What the battery actually measures #

Every vendor site got the same scan a paying customer gets: machine files on both hostnames, robots.txt parsed per agent, fifteen crawler identities fetching the homepage and compared against an unnamed client, schema read as an entity graph, the payload ratio of visible text to bytes, the render path, cache state on the machine files, and a nonexistent-path control so a firewall speaking for the site is recognised as one. Since this post was written the battery has grown by three sections, E-E-A-T proxies, an RDF reading of the schema, and accessibility structure, and the reports linked here regenerate under the current battery, so a vendor's number today may differ from the day we wrote this in either direction.

How to run the same check on any tool that grades you #

Before paying for an audit, scan the auditor. Fetch their robots.txt and llms.txt and read the content type, not the status. Fetch their homepage as GPTBot and as a browser and compare the byte counts. Look for an entity map. It takes two minutes and it tells you whether the advice you are about to buy is applied where the seller can see it. The guide to what each AI visibility tool measures does this for the category; a competitor graded us 100% and still sold us the fix is what it looks like from the other side.

Every figure above came out of this scanner.

Point it at your own domain and see the same measurements, free.

Scan a domain — free

The main product

Found this on your own site? We fix it for $749.

Scan free to see where you stand. The fix is one site, every finding implemented and re-measured, with a sealed before and after.

Questions this post answers

Do AI-visibility vendors follow their own advice?

Of 33 SEO and AI-visibility vendors run through the same scanner they would point at you, about a third publish llms.txt and none publish an entity map.

Is that a fair comparison?

It is the same checks, the same client and the same day for every vendor, and no vendor was told in advance.

What does it prove about the checks themselves?

That they are not niche requirements only a specialist can meet. The people selling the advice mostly have not implemented it.

Related findings

How anything measured in this article was measured15client identitiesone second, one address5machine filesapex and www114named agentsresolved from robots.txt24sections scoredreach, read, quoteHow anything measured here was measured15 client identities5 machine files114 named agents24 sections scoredone second, one addressapex and wwwresolved from robots.txtreach, read, quote
No account, nothing installed, and the same sequence on every domain — which is what makes one scan comparable to another. Run it on your own site.

Comments

Comments are read before they appear. Nothing is published automatically, and no account is needed.

Writing about this? Facts, live figures and marks — every number on that page is dated and traceable to a scan.

All findings · The dataset · How the dataset works